Know how long until you can work again
The question after any outage is never “do we have a backup?” It is “how long until the office, the phones and the EMR are working, and how much did we lose?” We manage your cloud, keep its cost honest, and make that answer a number you have tested.
Keep it running, keep it affordable, prove it can be restored
Microsoft 365 and Azure management
Your cloud accounts set up, secured and watched: subscriptions, identities, storage, and the cloud services your agency relies on, with someone accountable for them.
Cloud cost control
Budgets and alerts on every subscription, unused licenses reclaimed, over-sized services trimmed. Cloud bills drift upward quietly; we make them stop.
Backups that are tested
Microsoft 365 mail and files, laptops and servers backed up to a copy that ransomware cannot reach, with restore tests on a schedule and the result written down.
Disaster recovery planning
What gets restored first, by whom, in what order, and how long each piece takes. Written for the person who is stressed at 7 a.m., not for an auditor.
Downtime procedures
What field staff and the office do when the EMR, the internet or the phones are down: paper forms, a call tree, an on-call number that does not depend on the failed system.
Cloud migration
Moving file shares and old servers into SharePoint, OneDrive and Azure with a plan for permissions, cut-over and a way back.
Five required pieces, one plan you can show
The HIPAA Security Rule requires a contingency plan (45 CFR 164.308(a)(7)) so that PHI stays available when something goes wrong. It has five parts. We build each one for your actual systems and keep the evidence.
| Part | Plain meaning | Status |
|---|---|---|
| Data backup plan | Exact copies of PHI exist and can be retrieved | Required |
| Disaster recovery plan | How lost data and systems are restored | Required |
| Emergency mode operation plan | How you protect PHI and keep working while systems are down | Required |
| Testing and revision | You rehearse it and fix what the rehearsal finds | Addressable |
| Applications and data criticality | You know which systems to restore first | Addressable |
“Addressable” does not mean optional: you implement it, or document why an equivalent measure is reasonable.
The two numbers that decide how bad an outage is
How long can you be without it? (the recovery time) and how much work can you afford to lose? (the recovery point). We agree them with you, system by system, then check that your backups and plan really meet them.
| System | You decide |
|---|---|
| EMR access | Hours without it? Records you can re-enter? |
| Email and Teams | Hours without it? |
| Phones and call queues | Minutes before patients notice? |
| Payroll and billing files | How much recent work is acceptable to redo? |
| Shared documents | Which folders are critical? |
Microsoft’s retention is not a backup. Deleted or encrypted Microsoft 365 data can be gone for good. A separate backup is what lets you recover.
A backup you have not restored is a hope
- Regular file-level tests: pick a file, restore it, confirm it opens. We recommend this quarterly.
- An annual recovery drill: rebuild a key system from backup and time it, so the recovery time is a measurement, not a guess.
- A written result each time: what was tested, how long it took, what failed, what changed. This is evidence for your compliance file.
What a cloud cost review looks at
- Licenses assigned to people who have left, or never signed in
- Plans that include features nobody uses, or miss features you need
- Azure services running with no owner
- Storage and backup copies growing without a retention rule
- A monthly budget and an alert on every subscription, so a surprise bill becomes an email
Continuity in practice
Systems that tell you when they break, a phone system that falls back safely, and access you can reason about.
Every call answered or captured, with voicemails that become tasks
A Teams Phone menu routes callers by type, and unanswered calls become tracked tasks with a transcript instead of a blinking light.
A voicemail becomes a task in 8 seconds.
Running in productionRead the case study PlatformA one-click operations dashboard with an audit trail for every run
Recurring compliance and admin tasks became buttons on a Teams page, and every run leaves an append-only record an auditor can be shown.
Press a button; 43 seconds later the email, the Teams post and the audit row exist.
Running in productionRead the case study Identity and accessStaff access to resources without opening up the agency’s data
Overlapping groups and sites were consolidated by purpose, and care staff, most of them guests, get their own site without any path to office data.
14 groups became 9 plus one distribution list, each with a stated purpose.
Running in productionRead the case study